EMR Integration

HIPAA Texting Governance for Tebra Groups

Written by Mira Gwehn Revilla | Oct 5, 2026, 8:00:00 PM
💡 HIPAA-compliant texting governance for Tebra group practices puts every patient text, at every site, on one channel you control, log, and cover with a BAA. Each new site makes this harder, since its staff already text patients their own way.
  • Texts sent from personal phones leave no record the group can pull when a complaint or OCR request arrives.
  • Acquired sites carry texting habits that rarely come up in diligence.
  • HIPAA's audit controls standard (45 CFR 164.312(b)) expects activity in systems that hold ePHI to be recorded and reviewable.
  • Access should mirror Tebra's own model, where each login reaches only the practices that person needs.
  • Plain SMS should carry no clinical details, so results and balances go behind a secure link.
The fix that sticks is a sanctioned channel that beats a staff member's own phone on speed, live at every site on day one.

A patient at your first location texts to move her Thursday visit. The reply comes from the practice number, lands in a shared inbox, and shows who sent it.

Across town, at the clinic you bought last spring, another patient asks the same thing. That answer comes from a medical assistant's personal iPhone, where it joins years of threads the group has never seen.

Both patients got a fast reply. Only one of those replies exists anywhere you can find it.

We think HIPAA-compliant texting governance for Tebra group practices holds only when the approved channel is faster than a personal phone. Every new location also needs that channel on day one of the deal.

Tebra already gives you tight control over who sees what. Its user settings limit each login to the practices that person can access, in line with HIPAA's minimum necessary rule.

A text sent from a personal phone skips every one of those settings. It has no role, no practice scope, and no log.

For a group that grows by buying practices, this risk stacks up. Each deal adds staff, and each team brings the shortcuts it built over years of doing things its own way. Few of those shortcuts show up in diligence, because nobody on either side thinks to ask about them.

The owner usually carries what turns up later, often without a compliance team to call. That's why patient texting compliance in a growing group can't wait for the first complaint. It needs to be part of how you open, run, and absorb every site.

Shadow Texting

Shadow texting is patient texting that happens outside any system the group owns. It shows up at almost every location, and it starts for good reasons.

Why Staff Text From Their Own Phones

It works, and staff know it. A patient who can't reach the front desk by phone will text the number she has. Often that's the MA who helped her last time.

Compare the paths for one simple ask, like "Can I come at 3 instead of 2?" The portal route means a login the patient forgot, a message that waits in a queue, and a reply she may never see.

The phone route means one call, a hold, and maybe a voicemail. A personal text gets an answer in two minutes.

So staff reach for their own phones during the busy hours. Three patients are waiting to check in, the lines are ringing, and a text is the fastest way to clear one task. Nobody plans it. It becomes the habit because it saves time every single day.

What an Acquisition Brings Along

Diligence checklists are long. They cover payer contracts, leases, staff agreements, and the EHR move. Few of them ask, "Which phones do your staff use to text patients?"

That silence is where acquisition-inherited compliance risk hides. A common pattern plays out a few months after closing.

The owner learns that the acquired clinic's most loved MA has texted patients from her own phone since 2019. There are hundreds of threads with names, visit times, refill questions, and photos of rashes.

All of it sits on a device the group has never seen, can't search, and can't wipe. It's now the group's problem to manage.

The phone likely backs up to her personal cloud account too, so the threads live in a second place you don't control. If she quits next year, those records leave with her.

Patients who saved her number will keep texting it, and some will never learn the practice has a main line.

The Request You Can't Answer

Sooner or later, someone asks for the full record. It might be a patient complaint, a lawyer's subpoena, or an OCR inquiry. Each one wants every communication with a named patient.

Your team can pull Tebra notes and portal messages in an afternoon. Then comes the gap. Staff with PHI on a personal phone would have to hand over the device or send screenshots. You'd have no way to check that the set is complete.

"That happened before we owned them" doesn't help much either. Any text sent after closing came from your workforce, so the exposure keeps growing each week the habit goes on.

HIPAA's Security Rule has an audit controls standard, 45 CFR 164.312(b). It calls for ways to record and review activity in systems that hold electronic PHI. A personal phone offers none of that to the group.

Penalties can be steep. Under HHS's current inflation-adjusted penalty tiers, the top tier carries a yearly cap of $2,134,831 for the same type of violation.

Why a Policy Memo Loses

Most owners respond the same way. They add a line to the handbook and announce it at the next staff meeting: no patient texting from personal phones.

Two weeks later, the lines are still busy and patients still text the numbers they have. Staff face a choice between breaking a rule and letting a patient wait. Most pick the patient, and they're not wrong to care about her.

We'd go a step further. A ban without a faster tool pushes texting further out of sight, because staff stop mentioning it. Inherited habits are the hardest to move, since the acquired team built them long before your policy existed.

Signed policy forms don't help much here. An MA can sign the form on Monday and answer a patient from her own phone on Tuesday, and both acts feel reasonable to her.

The Compliance Backbone

Curogram gives each location one sanctioned texting channel, tied to the practice number and built to beat the personal phone on speed. When the approved path is also the quick one, staff move to it on their own, at old sites and new ones.

One Channel That Wins on Speed

Speed is the whole case for adoption. Staff reply from a shared inbox on a desktop or the mobile app. Saved templates handle the common asks, like directions, parking, forms, and "please arrive 15 minutes early."

Routing keeps the right person on each thread. A billing question goes to billing, and a reschedule goes to the front desk at that site. Nobody has to forward a screenshot.

Automation also takes load off the phones, which removes the reason staff started texting in the first place.

Based on our internal data, practices using automated texting saw inbound calls drop by 24%, and some cut phone volume by up to 50%. Fewer calls means fewer moments where a personal phone looks like the fastest fix.

Access Scoped by Location and Duty

Tebra already scopes users. Its practice access settings let an admin grant a login only to the practices that person needs. Your texting channel should follow the same logic.

With role-based access, a front desk user at the east clinic sees the east clinic inbox. A biller sees payment threads across the sites she covers. A regional manager sees everything in her region, and nobody sees more than their job needs.

Offboarding changes too. When an MA leaves, you turn off one login, and her patient threads stay with the practice. Compare that with asking a departing employee to delete years of texts from her own phone and trusting that she did.

An Audit Trail Across Every Location

Every message in the channel is logged with the sender, the time, the location, and the patient. That gives you an audit trail of patient texts across all locations, in one place.

When a request arrives, you search by patient and date range. The export shows the full thread, including who replied and when, so you're not piecing it together from memory. This is the kind of record the audit controls standard has in mind.

Curogram also pulls patient and appointment data from the EHR. Each thread sits against the right patient and visit, which cuts the mix-ups that happen when two patients share a name at different sites.

BAA and Vendor Paperwork

Any texting vendor that touches PHI is a business associate under HIPAA. Get a signed BAA from your texting vendor before a single patient message goes out. If a vendor won't sign one, that ends the talk. Curogram signs one.

Past the BAA, ask for proof. If a vendor sells itself as a SOC 2 patient messaging platform, request the full Type II report, check the dates it covers, and read the exceptions section. A logo on a sales page tells you very little.

Compliant Because Convenient

Success here has one number: 100% of patient texts on governed, logged channels. That includes every site, even the one you closed on last month. Getting there is a rollout job, and it's shorter than most owners expect.

A Sample 30-Day Rollout at an Acquired Clinic

This plan is illustrative. Adjust the timing to the size of the site and how many staff text today.

  1. On closing day, add the location to Curogram. Set up the practice number, and create logins by role using the same site limits as the clinic's Tebra practice access.
  2. In week 1, load your group's templates, including the rule that PHI goes through a secure link. Walk the front desk through the shared inbox during a slow hour, not at 8 a.m.
  3. That same week, ask staff, without blame, which phones they've used to text patients. You can't fix threads you don't know about.
  4. During week 2, staff send a short closing text from their personal phones: "Please text us at the office number from now on." Active threads move to the practice line.
  5. At week 4, run a spot check. Pick five patients, pull their full text history, and confirm every message came through the governed channel.

Inherited Governance

After the rollout, each new deal brings your standard to their site, with the same templates, roles, and export process from week one.

That matters most for groups that close two or three deals a year. A new site manager learns one system, and your compliance lead reviews one log.

Track the 100% goal with two simple checks each month. Ask each site lead whether any staff still text patients from personal phones, and pull a spot sample of five patient histories per site. When both come back clean for three months, the site is done.

Staff keep what they wanted in the first place. Replies are still fast, patients still text a number they know, and the MA still gets to help people quickly. The only change is where the thread lives.

 

Curogram Highlight: Role-Based Access & Audit Trails

Role-Based Access & Audit Trails is how Curogram keeps texting governed as a Tebra group adds sites. Each user gets a login scoped to their location and their job. Each message is logged with who sent it, when, from which site, and to which patient.

For owners, the daily value is control without a security team. You add a location and set roles, and the new site's running under the same rules as the rest. When someone leaves, you turn off one login and the threads stay with the practice.

For staff, the value is speed. Templates cover the common asks, routing sends each thread to the right person, and the shared inbox means nobody's stuck guarding a single phone. Automated reminders and two-way replies take pressure off the phones, which is the pressure that started shadow texting.

The same channel handles the work that fills a day. Based on our internal data, Covina Arthritic Clinic confirmed an average of more than 1,100 appointments a month through automated texts. One multi-location practice saw 1,240 patients come back from SMS recall messages alone. Every one of those messages sits in the same governed log.

Content rules are built in. Default templates keep PHI out of the text body, and results or balances go through a secure link or encrypted messaging. Curogram signs a BAA, and patient and visit data flows in from the EHR so each thread sits against the right record.

When an audit request comes in, you search by patient and date, then export the full history across every location.

Conclusion: Make Governance Part of the Integration Playbook

Patients will keep texting, and staff will keep answering from whatever gets the reply out fastest. What an owner controls is which channel is fastest, and whether every site has it on the day you close.

Tebra runs your practice operations, from scheduling to claims. Curogram carries the everyday conversations around them, held to the same standard at every door you own. Together they give each new location a clear setup: Tebra for the chart and the schedule, a governed channel for the texts.

Before your next deal, ask one question about your last one. "Could we produce every patient text from their last quarter?" If the answer takes more than a second, act on that pause.

Start with the acquired sites, since that's where habits are oldest and least visible. Then fold the same rollout into your standard integration list, so the next clinic gets it with payroll and the EHR move.

Schedule a demo with our team. We'll walk you through the access settings and a sample audit export, and our BAA terms are ready for your review.

 

Frequently Asked Questions